Legal
Privacy Policy
Effective date: 22 September 2024 · Last updated: 8 June 2026
By using our website, mobile applications or services, you agree to this Privacy Policy. Please also review the Cookies section below for how we use cookies and similar technologies.
At Epic Escapes Limited (“we”, “us” or “our”), we take your privacy seriously. This Privacy Policy explains how we collect, use, share and protect your personal information when you visit our website at www.epic.africa, use our mobile applications, or engage with our services (together, the “Platform”, operated under the trading name Epic Africa). We act as a data controller under the Data Protection Act, 2019 of Kenya and are committed to processing your personal data in a transparent, fair and lawful manner.
1. Scope of this Privacy Policy
This Privacy Policy applies to:
- Visitors to our website, mobile applications and other digital platforms.
- Customers who make travel-related bookings through our services, including accommodation, activities, tours, dining, events, experiences and transportation.
- Business owners and hosts who list and manage products and services on the Platform.
- Individuals who subscribe to marketing communications or otherwise interact with us via various channels.
It explains how we collect, store, use and share your personal information when you book or enquire about a service, contact our support teams, or interact with us on social media, third-party websites or partner platforms.
2. What personal data we collect
2.1 Information you provide
- Personal identification: full name, email address, postal address, phone number, date of birth and nationality.
- Booking information: travel preferences, accommodation and activity details, travel dates and quantities, the names of those travelling with you, and any special requests or dietary needs.
- Account information: login credentials and preferences you set (such as language or currency).
- Business owner / host information: business and listing details, inventory and pricing, payout details, and identity-verification (Know Your Customer, “KYC”) information required to verify you and enable payouts.
- Payment information: billing details and transaction records. Payment card details are entered and processed directly by our payment provider (see Section 6); we do not store your full card number or banking credentials.
- Feedback and reviews: which we may display on the Platform with your first name or an alias you choose.
- Communications: messages, enquiries and correspondence with our teams.
2.2 Information we collect automatically
- Device and browser information: IP address, browser type, operating system, device make and model, and language preferences.
- Usage data: pages viewed, links clicked, searches, and your interactions with our features and bookings.
- Geolocation data: with your consent, location information used to provide location-specific services and recommendations.
- Security data: information used to protect the Platform, including IP handling and bot-verification challenges provided through our security provider (Cloudflare / Turnstile).
- Cookies and similar technologies: see Section 7.
2.3 Information from third parties
- Booking partners and travel agencies: contact and booking details when you book through a partner.
- Social media platforms: if you sign in using a social account (such as Facebook, Instagram or Google), we may receive profile information (such as your name, profile picture and contact details) depending on your settings on those platforms.
- Service providers: such as payment processors, analytics and advertising providers, in accordance with their own privacy policies.
3. How we use your personal data
3.1 Providing our services
- Processing and confirming your bookings for accommodation, transportation, activities, dining, events and experiences.
- Communicating with you about booking status, updates and itineraries.
- Handling payments and refunds securely.
3.2 Enabling hosts
Creating and managing host accounts and listings — including inventory, availability and pricing — verifying host identity (KYC), and processing payouts.
3.3 Customer support
Using your contact details and booking history to assist with enquiries, troubleshoot issues, resolve disputes and respond to feedback.
3.4 Communication and marketing
With your consent, we may send promotional offers, recommendations, updates, newsletters and surveys relevant to your interests. You can opt out at any time using the “unsubscribe” link in our emails or by contacting us at [email protected].
3.5 Personalisation and analytics
Tailoring content, recommendations and advertisements to your interests, and understanding how users interact with the Platform so we can improve it.
3.6 Legal compliance and security
- Preventing fraud, abuse and other illegal activity.
- Complying with legal obligations and valid requests from authorities, such as law enforcement or tax authorities.
- Ensuring the security and integrity of our systems, website and users.
4. Lawful bases for processing
Under the Data Protection Act, 2019, we rely on one or more of the following lawful bases: performance of a contract (to provide bookings and services); your consent (for example, marketing and geolocation); compliance with legal obligations; and our legitimate interests (such as security, fraud prevention and improving the Platform). Where we rely on consent, you may withdraw it at any time.
5. How we share your data
We do not sell your personal data. We share it only where necessary to provide our services or comply with the law.
5.1 Service providers and partners
- Accommodation providers, hosts and travel partners: the details needed to fulfil your booking (such as your name and contact information).
- Payment processors: to complete transactions securely (see Section 6).
- IT, hosting and security providers: including website hosting, data storage, email distribution and security services (such as Cloudflare).
- Analytics and advertising partners: to measure and improve the Platform and tailor content and ads.
5.2 Legal and regulatory authorities
Where required by law or in response to valid requests, including to prevent fraud, resolve disputes, or protect the rights of Epic Escapes Limited and our users.
5.3 Business transfers
In the event of a merger, acquisition or sale of all or part of our business, your data may be transferred to the successor entity as part of the transaction.
6. Payments
Payments are processed securely by Paystack. Your payment card details are entered and handled directly by Paystack under its own terms and privacy policy. We receive the outcome of each transaction and retain only limited records — such as a payment reference, amount, currency, email and status — for order management, refunds and legal compliance. We do not store your full card number or banking credentials.
7. Cookies and tracking technologies
We use cookies and similar technologies to improve your experience, analyse traffic, and deliver relevant content and advertising. Cookies are small text files placed on your device when you visit the Platform.
7.1 Types of cookies we use
- Essential cookies: necessary for the Platform to function, including booking, secure areas and bot/security checks.
- Functional cookies: remember preferences such as language or currency.
- Analytics cookies: help us understand how the Platform is used so we can improve it.
- Advertising cookies: display relevant ads and measure the effectiveness of marketing campaigns.
7.2 Managing cookies
You can manage your preferences through our cookie banner (where shown) and your browser settings. Blocking some cookies may affect functionality. For more information, visit allaboutcookies.org.
8. International data transfers
Some of our service providers may process data outside Kenya. Where we transfer personal data internationally, we apply appropriate safeguards consistent with the Data Protection Act, 2019.
9. Data security and retention
We implement appropriate technical and organisational measures — including encryption, secure storage, access controls and fraud monitoring — to protect your data from unauthorised access, misuse, loss or alteration. No system is completely secure, but we work to safeguard your data and respond promptly to incidents.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, comply with legal obligations, resolve disputes and enforce our agreements. When it is no longer needed, it is securely deleted or anonymised.
10. Your rights
Subject to the Data Protection Act, 2019, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your data, subject to exceptions where we must retain it for legal or legitimate reasons.
- Object to processing, in particular for direct marketing.
- Restrict processing in certain circumstances.
- Data portability — request transfer of your data to another provider.
- Withdraw consent at any time where processing is based on consent.
To exercise your rights, contact us at [email protected]. You also have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) of Kenya.
11. Children’s privacy
The Platform is not directed at children, and we do not knowingly collect their personal data without appropriate consent. If you believe a child has provided us with personal data, please contact us so we can take appropriate action.
12. Third-party links
The Platform may contain links to third-party websites and services that we do not control. This Privacy Policy does not apply to those sites, and we encourage you to review their own privacy policies.
13. Changes to this Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, legal requirements or services. Significant changes will be communicated by email or by posting a notice on the Platform. Please review this page regularly; the “Last updated” date above shows when it was last revised.
14. Contact us
If you have any questions or concerns about this Privacy Policy or our handling of your personal data, please contact:
Epic Escapes Limited (trading as Epic Africa)
Branton Court, Maisonette A6, Ndemi Lane, Off Ngong Road,
P.O. Box 19893–00100, Nairobi, Kenya
Email: [email protected]
You can also reach us through our contact page.